RAXE Intelligence

Every detection is open. Read the signature.

Original threat research from RAXE Labs becomes the detection signatures that ship in the platform–open, auditable, and every one mapped to MITRE ATLAS and OWASP ASI. Read exactly what fires and why.

Book a 30-min walkthrough → Read the advisories (47 published) Threat Intelligence
Open Signatures

Open, auditable signatures

Every detection signature is open and auditable–you can read exactly what fires and why–and every one is mapped to MITRE ATLAS techniques and OWASP ASI categories. No black boxes, and no signature counts inflated for a slide. The content is the claim. Two signatures, side by side: one prompt-side, one cloud-side.

Prompt-side · S4
Illustrative sample
id: raxe-pi-001
name: direct_instruction_override
family: prompt_injection
severity: high
confidence: 0.9
stream: S4
mitre_atlas: AML.T0051
owasp_asi: ASI01
patterns:
  - "ignore (all |any )?(previous |prior )?instructions"
  - "disregard (your |the )?system prompt"
  - "you are now (a |an )?[\\w]+ (mode|assistant)"
action: detect
Cloud-side · AWS CloudTrail
Illustrative sample
id: raxe-aws-exfil-001
name: Agent Role Reads Production Secret
severity: high
surface: aws-cloudtrail
api_action: secretsmanager:GetSecretValue
identity: agent execution role
finding: data-exfiltration
mitre_atlas: AML.T0025
owasp_asi: ASI04
action: detect

Detections from your own CloudTrail, correlated to agent sessions–not exact attribution. How the AWS lane works →

Shared Taxonomy
One vocabulary from rule hit to analyst verdict. Every signal in the platform speaks the same taxonomy: 13 threat families, 41 techniques, 10 harm types. A rules hit, an ML verdict, and an analyst note all land in the same categories–mapped to MITRE ATLAS and OWASP ASI, the frameworks built for AI-agent threats.
4 Research Streams

Where the findings come from

S1

Adversarial ML

Model exploitation, jailbreaks, adversarial inputs.

S2

Agent Security

Tool-use abuse, MCP vulnerabilities, sandbox escapes.

S3

Supply Chain

AI/ML frameworks, registries, pipeline dependencies.

S4

Prompt Injection

Direct, indirect, and web-based injection against agents.

Where It Lands

One research pipeline. Five detection signals.

Intelligence feeds every signal in the detection stack–named honestly, one by one.

Signal 1

ATLAS + ASI-Mapped Rules

New techniques from advisories and research streams become open signatures, each tagged to MITRE ATLAS and OWASP ASI.

Signal 2

ML Text Scorer

Research corpora feed the training and evaluation of the text scorer–so verdicts return a threat probability and per-family scores, not just a label.

Signal 3

Structured Tool-Call Risk Analysis

New injection classes found in the wild become argument-level checks: SQL injection, shell injection, and path traversal inside tool-call parameters.

Signal 4

Agent Behaviour Graph

Multi-step attack patterns documented in research inform the sequences the behaviour graph surfaces across an agent session.

Signal 5 · Opt-in

Advisory LLM Judge

An optional second opinion on borderline text, tuned against research-derived boundary cases. Evidence, never authority–it never changes the decision.

How Intelligence Connects
Research becomes detection. Every signature, advisory, and technique mapping produced by RAXE Intelligence is shipped to RAXE Gateway, RAXE Sensor, and the AWS cloud detection lane in the next platform release. Gateway scores AI API traffic. Sensor observes execution where agents run. The AWS lane raises detections from your own CloudTrail. Intelligence provides the signatures and mappings that power all three. Today it lets you see it. Next, it lets you stop it.
Early access – design partner programme

Put the research to work

Read the research in the open, or see the detection signatures running on your own stack.

Book a 30-min walkthrough → See how it deploys Talk to an Engineer
Security Advisories → Threat Intelligence →